CVE-2006-1326: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) resulttype, (2) searchin, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sortorder, (15) maxresults, or (16) sortkey parameter in a Members action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1326?
CVE-2006-1326 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2006-1326?
To mitigate CVE-2006-1326, you should upgrade Invision Power Board to the latest version that addresses these XSS vulnerabilities.
What vulnerabilities does CVE-2006-1326 exploit?
CVE-2006-1326 exploits multiple cross-site scripting vulnerabilities in Invision Power Board 2.0.4.
Who is affected by CVE-2006-1326?
Any user running Invision Power Board version 2.0.4 is affected by CVE-2006-1326.
Can CVE-2006-1326 be exploited remotely?
Yes, CVE-2006-1326 can be exploited remotely by attackers through specially crafted requests.